Default ICS Credentials Exploited in Destructive Attack on Polish Energy Facilities

Default ICS Credentials Exploited in Destructive Attack on (TL-2026-0053) is a critical-severity ICS/SCADA threat scored CVSS 9.8, first published 2026-02-03. It is attributed to Sandworm (Russia) with medium confidence, affects Multiple Industrial Control Systems, maps to 60 MITRE ATT&CK techniques (T0800, T0801, T0802), and is covered by 15 detection rules and 42 indicators of compromise.

Key facts for TL-2026-0053

Threat ID
TL-2026-0053
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
ICS_SCADA
First published
2026-02-03
Last reviewed
2026-02-03
Attribution
Sandworm
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
SABOTAGE
Target sectors
Energy, Critical Infrastructure, Electric Utilities, Water and Wastewater, Oil and Gas, Manufacturing, Building Automation
Target regions
Poland, Ukraine, NATO Countries, European Union, United States, Baltic States
Detection rules
15
Indicators of compromise
42

Default, hardcoded, and well-known credentials in Industrial Control System (ICS) and SCADA components are actively exploited in destructive attacks against Polish energy infrastructure, representing the credential exploitation companion to the Static Tundra campaign (TL-0004/TL-0014/TL-0037). ICS protocols (Modbus TCP, DNP3, OPC-UA, BACnet, EtherNet/IP) were designed for isolated networks without authentication, and legacy devices ship with default credentials documented in publicly available manuals. Attackers leverage default vendor credentials (admin/admin, operator/operator, root/password, factory-set community strings) to gain direct control of PLCs, RTUs, HMIs, and SCADA servers — bypassing IT security controls entirely via the IT-to-OT pivot. CISA, NSA, and NIST SP 800-82r3 have repeatedly warned that default ICS credentials represent the single most exploitable weakness in critical infrastructure, yet surveys consistently find 30-60% of ICS devices running with factory-default credentials in production.

How Default ICS Credentials Exploited in Destructive Attack on works

Default ICS Credentials: The Persistent Root Cause of Critical Infrastructure Compromise

The Problem — Authentication-Free by Design:

Industrial Control Systems were designed in the 1970s-1990s for isolated, air-gapped networks where physical security was the only access control. Protocols like Modbus (1979), DNP3 (1993), and BACnet (1995) have NO built-in authentication, encryption, or access control. Any device on the network can read/write to any controller. When these systems were connected to IT networks and eventually the internet, the authentication vacuum became the single largest attack surface in critical infrastructure.

Default Credential Categories in ICS:

1. Vendor-Shipped Default Credentials (Most Common): - PLC/RTU login: admin/admin, admin/password, root/root, operator/operator - HMI default accounts: factory/factory, engineer/engineer, user/user - SCADA server: administrator with vendor-specific default password - SNMP community strings: 'public' (read) and 'private' (read-write) — the most exploited default in ICS - Web interface: vendor-specific default (often documented in product manual available online)

2. Hardcoded Credentials (Cannot Be Changed): - Firmware service accounts with compiled-in credentials - Debug/maintenance backdoor accounts - OEM access accounts for vendor remote support - Protocol-level credentials embedded in firmware (Modbus unit IDs, DNP3 addresses) - These persist even after 'default password change' because they exist at a different level

3. Well-Known Protocol Defaults: - Modbus TCP: NO authentication at all — any network access = full read/write control - DNP3: Optional authentication rarely enabled (Secure Authentication v5 exists but adoption <10%) - OPC-UA: Certificate-based auth available but many deployments use anonymous mode - BACnet: No authentication — designed for building automation, now in energy management - EtherNet/IP: No built-in authentication — CIP protocol allows direct PLC programming - ICCP (IEC 60870-6): Inter-control center communications with minimal authentication

4. Shared/Generic Credentials: - Single password shared across entire OT environment ('the plant password') - Generic accounts: 'operator1', 'maintenance', 'engineering' with plant-wide passwords - VPN credentials for remote access shared among vendors, contractors, and staff - Engineering workstation local admin passwords identical across all machines

Polish Energy Grid Context:

Poland's energy infrastructure combines legacy Soviet-era ICS equipment with modern EU-standard systems during an ongoing energy transition. The grid includes: - Polskie Sieci Elektroenergetyczne (PSE) — transmission system operator (400kV/220kV/110kV) - 5 major distribution system operators (DSOs) covering 16 voivodeships - 70+ conventional power plants (coal, gas, nuclear planned at Żarnowiec) - Rapidly growing renewable capacity (18+ GW wind/solar by 2026) - Cross-border interconnections with Germany, Czech Republic, Slovakia, Lithuania, Sweden

The legacy-to-modern transition creates a mixed environment where modern SCADA systems with authentication capabilities coexist with legacy RTUs and PLCs running Modbus TCP without any authentication. These legacy devices cannot be upgraded — they must be replaced, which requires physical access during scheduled outages.

Attack Progression — IT to OT Pivot:

1. Initial Access to IT Network: - Spearphishing (APT28 Operation Neusploit — TL-0052) - VPN credential compromise (default/shared credentials) - Internet-facing IT systems with known vulnerabilities

2. IT-to-OT Pivot (The Critical Boundary): - Engineering workstation with both IT and OT network access - Historians/data servers bridging IT/OT networks - Improperly segmented SCADA DMZ - VPN concentrators with OT network access - USB transfer stations (air-gap bridge)

3. OT Network Reconnaissance: - Passive network sniffing (Modbus/DNP3 traffic in plaintext) - Active scanning with ICS-aware tools (Nmap ICS scripts, PLCScan) - SNMP enumeration with default community strings - HMI/SCADA web interface discovery

4. ICS Device Access via Default Credentials: - PLC programming access with default engineering passwords - RTU configuration modification with vendor defaults - HMI login with factory credentials - SCADA server admin access with default accounts

5. Destructive Payload Execution: - PLC logic manipulation (false readings, protective relay disabling) - RTU configuration overwrite (incorrect setpoints, tripped breakers) - HMI display manipulation (operators see normal readings while physical process diverges) - Safety instrumented system (SIS) bypass (disabling automatic safety shutdowns) - Firmware overwrite (brick PLCs requiring physical replacement)

Historical Precedent — ICS Default Credential Attacks:

- Ukraine 2015 (BlackEnergy/Sandworm): Default VPN and HMI credentials enabled SCADA access → 230K customers lost power for 6 hours - Ukraine 2016 (Industroyer/CrashOverride): Direct ICS protocol manipulation (IEC 104, IEC 61850) — no authentication needed - Saudi Arabia 2017 (TRITON/TRISIS): Schneider Electric Triconex SIS — hardcoded firmware credentials enabled safety system manipulation - Oldsmar Florida 2021: TeamViewer remote access with shared password → sodium hydroxide levels manipulated - Colonial Pipeline 2021: Compromised VPN credentials (legacy account, no MFA) → $4.4M ransom, 6-day pipeline shutdown - Denmark Wind Turbines 2023: Default credentials on Enercon/Vestas turbine SCADA → 11 GW disconnected - Multiple US water utilities 2023-2024: Default Unitronics PLC passwords → Iranian CyberAv3ngers campaign, CISA advisory

Scale of the Problem:

- CISA ICS-CERT: Default credentials cited in >40% of ICS advisories (2019-2025) - Claroty Team82: 30% of ICS devices in production run default credentials (2024 survey) - Dragos: 60% of ICS environments have at least one device with default credentials - NIST SP 800-82r3: Lists default credential elimination as top priority recommendation - ICS-CERT scans: Average energy utility has 20-50 devices with default/hardcoded credentials - Shodan: 100K+ ICS devices internet-accessible, majority with default configurations

MITRE ATT&CK techniques used in TL-2026-0053

inhibit-response-function

T0800 Activate Firmware Update Mode

Collection

T0801 Monitor Process State; T0802 Automated Collection; T0861 Point & Tag Identification; T0868 Detect Operating Mode

Impair Process Control

T0806 Brute Force I/O; T0836 Modify Parameter; T1692.001 Command Message

Inhibit Response Function

T0809 Data Destruction; T0814 Denial of Service; T0816 Device Restart/Shutdown; T0838 Modify Alarm Settings; T1691.002 Reporting Message

Initial Access

T0818 Engineering Workstation Compromise; T0847 Replication Through Removable Media; T0860 Wireless Compromise; T0862 Supply Chain Compromise; T0866 Exploitation of Remote Services; T0883 Internet Accessible Device; T0886 Remote Services

Evasion

T0820 Exploitation for Evasion; T0851 Rootkit; T1692.002 Reporting Message

Execution

T0821 Modify Controller Tasking; T0853 Scripting; T0858 Change Operating Mode; T0871 Execution through API

Discovery

T0824 I/O Module Discovery; T0842 Network Sniffing; T0846 Remote System Discovery

Impact

T0826 Loss of Availability; T0827 Loss of Control; T0828 Loss of Productivity and Revenue; T0831 Manipulation of Control; T0837 Loss of Protection; T0879 Damage to Property; T0880 Loss of Safety; T0882 Theft of Operational Information

Lateral Movement

T0843 Program Download; T0859 Valid Accounts

Command and Control

T0885 Commonly Used Port

Persistence

T0889 Modify Program; T1693.001 System Firmware; T1693.002 Module Firmware; T1694.002 Hardcoded Credentials

credential-access

T1003 OS Credential Dumping; T1110 Brute Force; T1552 Unsecured Credentials

lateral-movement

T1021 Remote Services; T1570 Lateral Tool Transfer

discovery

T1046 Network Service Discovery

execution

T1059 Command and Scripting Interpreter

defense-evasion

T1070 Indicator Removal; T1078 Valid Accounts; T1078.001 Default Accounts

command-and-control

T1071 Application Layer Protocol

persistence

T1133 External Remote Services; T1694.001 Default Credentials

impact

T1485 Data Destruction

initial-access

T1566 Phishing

Affected products and versions in Default ICS Credentials Exploited in Destructive Attack on

  • Multiple — Industrial Control Systems
    Vulnerable versions: Systems with default credentials
    Fixed in: N/A - configuration issue

Remediation for Default ICS Credentials Exploited in Destructive Attack on

Patches

  • Siemens SIMATIC S7-1500 firmware updates with access protection features
  • Schneider Electric Modicon firmware updates removing hardcoded accounts
  • Rockwell CIP Security firmware for ControlLogix/CompactLogix
  • Unitronics firmware update from default password '1111'

Immediate actions

  • Inventory ALL ICS devices and identify those running default credentials — use ICS asset discovery tools (Claroty, Nozomi, Dragos)
  • Change all default passwords on PLCs, RTUs, HMIs, SCADA servers, and engineering workstations immediately
  • Disable or change default SNMP community strings ('public'/'private') on ALL network-connected ICS devices
  • Verify IT-OT network segmentation — ensure no direct path from IT network to ICS devices without firewall/DMZ
  • Disable remote access (TeamViewer, VPN, RDP) to ICS devices unless absolutely required — enforce MFA where enabled

Workarounds

  • Network segmentation as compensating control for devices that cannot be patched — isolate legacy Modbus devices behind protocol-aware firewalls
  • Deploy unidirectional security gateways (data diodes) for historian data flow — prevents IT-to-OT command injection
  • Implement network allowlisting — only permit known engineering workstation MACs/IPs to communicate with PLCs
  • Monitor all ICS protocol traffic for anomalous commands — any PLC programming outside maintenance windows is suspicious

Longer-term hardening

  • Implement IEC 62443 zone-and-conduit network architecture with strict IT/OT boundary enforcement
  • Deploy ICS-aware network monitoring (Dragos, Claroty, Nozomi Networks) for protocol-level anomaly detection
  • Implement individual user accounts on all ICS systems — eliminate shared/generic credentials ('operator1', 'maintenance')
  • Deploy certificate-based authentication where supported (OPC-UA certificates, CIP Security TLS)
  • Establish credential rotation schedule for ICS devices (quarterly minimum) with documented procedures for each device type
  • Replace legacy devices that cannot support authentication (Modbus-only RTUs) with modern equivalents during scheduled outages

Weaknesses (CWE) in Default ICS Credentials Exploited in Destructive Attack on

CWE-798, CWE-1392

Timeline of Default ICS Credentials Exploited in Destructive Attack on

  • Modbus protocol created by Modicon for PLC communication. Designed for isolated serial networks with NO authentication, encryption, or access control. Any device on the network can read/write to any PLC register. Still the most widely deployed ICS protocol in 2026.
  • DNP3 (Distributed Network Protocol) published for electric utility SCADA. Optional authentication added in DNP3 Secure Authentication v5 (2012) but adoption remains below 10% in production deployments. Most DNP3 installations operate without authentication.
  • Stuxnet worm discovered targeting Siemens S7-300 PLCs in Iranian nuclear facilities. Exploited default Siemens WinCC database password ('2WSXcder'). Watershed moment demonstrating ICS vulnerability. NIST and CISA prioritize ICS security guidance.
  • BlackEnergy/Sandworm attack on Ukrainian power grid. Default VPN credentials and HMI passwords enabled SCADA access. 230,000 customers lost power for 6 hours. First confirmed cyberattack causing power outage. Source: SANS ICS analysis.
  • Industroyer/CrashOverride attack on Ukraine's Ukrenergo transmission. Directly manipulated IEC 104/IEC 61850 protocols — no authentication needed at protocol level. 200MW load shed for 1 hour. Demonstrated protocol-level exploitation without credentials.
  • TRITON/TRISIS malware targets Schneider Electric Triconex Safety Instrumented System at Saudi Arabian petrochemical facility. Hardcoded firmware credentials in Triconex enabled safety system manipulation. Could have caused physical destruction/harm. Source: Mandiant/FireEye.
  • Oldsmar, Florida water treatment attack. TeamViewer remote access with shared password (no MFA) → attacker increased sodium hydroxide to dangerous levels. Default/shared remote access credential exploitation. Detected by operator monitoring HMI.
  • Colonial Pipeline ransomware attack via compromised VPN credential (legacy account, no MFA, password reuse). 6-day pipeline shutdown, $4.4M ransom paid. Single default/reused credential → $4.4B economic impact. Source: CISA advisory.
  • NIST publishes SP 800-82 Revision 3 — Guide to OT Security. Elevates default credential elimination to top-priority recommendation. Provides comprehensive ICS/SCADA security framework. Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-82r3.pdf
  • Iranian CyberAv3ngers exploit default password '1111' on Unitronics Vision PLCs at multiple US water utilities. CISA issues advisory AA23-335a. Default factory password never changed on internet-accessible PLCs. Demonstrated nation-state exploitation of default ICS credentials.
  • Claroty Team82 reports 30% of ICS devices in production environments run with default credentials. Dragos reports 60% of ICS environments have at least one device with default credentials. ICS-CERT cites default credentials in >40% of ICS advisories.
  • Poland accelerates energy transition: 18+ GW renewable capacity, nuclear program at Żarnowiec, cross-border interconnections with Germany/Czech Republic/Slovakia/Lithuania/Sweden. Mixed legacy-modern ICS environment creates authentication gaps at legacy device boundaries.
  • Static Tundra reconnaissance of Polish energy infrastructure detected. Scanning for Modbus/DNP3 endpoints, SNMP enumeration with default community strings, HMI web interface discovery. Pre-positioning for destructive attack using default credential access vectors.
  • Destructive attack on Polish energy infrastructure via default ICS credentials. IT-to-OT pivot through engineering workstation → Modbus TCP direct PLC access (no auth) → protective relay manipulation → localized grid disruption. Default SNMP community strings enabled initial OT network mapping.
  • EU Network and Information Systems Directive (NIS2) enforcement begins. Mandates ICS security including credential management, network segmentation, and incident reporting for essential service operators. Polish energy sector compliance deadlines. Penalties up to €10M or 2% of revenue.
  • Threadlinqs Intelligence analysis: Default ICS credentials are the persistent root cause of critical infrastructure compromise. 47 years after Modbus (1979), protocols still lack authentication. 30-60% of ICS devices run factory defaults. The credential IS the control — when it's 'admin/admin', there IS no control. Physical replacement of legacy devices is the only permanent fix.
  • As of 2026-05-29, this remains ACTIVE: the Dec-2025 DynoWiper attack on ~30 Polish energy sites (default ICS creds + FortiGate VPN pivot) was contained, but CISA's Feb-2026 alert confirms 30-60% of ICS still run factory defaults and no patch closes the design flaw. Attributed actor Sandworm/APT44 (GRU) is undisrupted, with Microsoft/Amazon reporting sustained 2026 Western-infrastructure targeting.

Sources cited for Default ICS Credentials Exploited in Destructive Attack on

Threats related to Default ICS Credentials Exploited in Destructive Attack on

Detection coverage for TL-2026-0053

As of 2026-02-03, Threadlinqs Intelligence publishes 15 detection rule(s) for TL-2026-0053 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats